Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-5350

EPSS 0.18% · P39
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-5350

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system that the BOSH-created vcap user has permissions to read and then package them into their app droplet.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Pivotal Garden 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pivotal Garden是美国Pivotal Software公司的一套容器化系统。 Pivotal Garden 0.22.0-0.329.0版本中的garden-linux nstar可执行性文件存在安全漏洞。攻击者可利用该漏洞访问主机系统上的文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Dell EMCGarden Nstar Garden versions 0.22.0-0.329.0 -

II. Public POCs for CVE-2015-5350

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-5350

登录查看更多情报信息。

Same Patch Batch · Dell EMC · 2018-03-19 · 7 CVEs total

CVE-2014-3626Pivotal Grails Resources插件路径遍历漏洞
CVE-2018-1195Cloud Controller、cf-deployment和cf-release 安全漏洞
CVE-2018-1196Pivotal Spring Boot 安全漏洞
CVE-2018-1197Cloud Foundry Windows Stemcells 安全漏洞
CVE-2018-1218Dell EMC NetWorker 跨站脚本漏洞
CVE-2018-1221Pivotal Cloud Foundry cf-deployment 和routing-release 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2015-5350

No comments yet


Leave a comment